PT-2014-2388 · Mongodb · Mongodb

Ratul Gupta

·

Published

2014-02-17

·

Updated

2014-05-07

·

CVE-2012-6619

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions MongoDB versions prior to 2.3.2
Description The issue concerns the default configuration of MongoDB, where objects are not validated. This allows remote authenticated users to cause a denial of service or read system memory by sending a crafted BSON object in the column name of an insert command. This action triggers a buffer over-read.
Recommendations For versions prior to 2.3.2, update to version 2.3.2 or later to resolve the issue. As a temporary workaround, consider validating objects before processing them to prevent potential exploitation. Restrict access to the insert command to minimize the risk of denial of service or system memory exposure.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6619
MGASA-2014-0083
RHSA-2014:0230
RHSA-2014:0440

Affected Products

Mongodb